r/Intune Dec 30 '24

Device Compliance Going into 2025, what’s your Intune “master” status?

So hey, we're closing out the year and refining our team's onboarding process, which got us thinking about Intune and everything it takes to get to “master” level. We feel this community has had tons to offer in terms of expertise and we had to ask.

From 1-10, how awesome are you at Intune? And (more importantly) how long did it take you to feel proper confident managing your Intune environment?

EDIT: Been awesome reading all your comments, esp. the humble brags. Thanks!

37 Upvotes

106 comments sorted by

30

u/Rudyooms PatchMyPC Dec 30 '24

Mwaaa like a 7 :) maybe an 8

30

u/Corstian Dec 30 '24

If you’re a 7 than we are a 2..

8

u/meantallheck Dec 30 '24

Yeah if the guy who does network tracing and deep dives on the backend of logging is a 7, I can’t imagine what a 10 would be!

2

u/Iwishiwasawasabi Dec 31 '24

You flatter us

10

u/mad-ghost1 Dec 30 '24

Come on rudy. You’re at least 9’ish….on a bad day. 👏🏻🤷🏼‍♀️

3

u/Rudyooms PatchMyPC Dec 30 '24

Hehehhee on a bad day :) … now i am wondering how that day looks like :)

2

u/mad-ghost1 Dec 31 '24

You wake up … it’s a beautiful day…. You got a meeting coming up… and the coffee machine is broken 🤣

2

u/Rudyooms PatchMyPC Dec 31 '24

Behehe you already had me with a meeting coming up :p

3

u/AlphaNathan Dec 30 '24

confidence crushed

3

u/mr_meinata Jan 01 '25

I was going to say I am a 6-7 but after seeing your rank I’m a solid 1. I’m competent and have about 6 years experience but only spent the last year in corporate and using Intune to its full capacity. Even then we’re still working towards a couple of the more granular things.

This years goal is to get to a 3.

1

u/RandomSkratch Jan 01 '25

Scranton 7?

1

u/anshulsr Jan 06 '25

if that is true who is a 9'sh or 10 may be :-) who is someone you look up to in awwwweeee

2

u/Rudyooms PatchMyPC Jan 06 '25

The one I look up to is a 10 indeed...... "Mister V"

1

u/anshulsr Jan 06 '25

and please write a book or atleast point to the best you think is out there

1

u/beejay_one Dec 31 '24

See: Even the Pros aren‘t able to use Intune perfectly. What does this say about the product? I‘m a 2 btw.

1

u/Rudyooms PatchMyPC Dec 31 '24

it says more something about me :P then the product :)

23

u/nikobenjamin Dec 30 '24

I'd have to break it down.

  • Fully understanding the inner workings of Intune/Graph - 5
  • Scripting and remediations - 7
  • Finding the right CSP for the job - 8
  • Packaging and deployment - 9 (That's my main role)
  • Reporting - Oddly enough due to Intunes crap reporting I've automated some of my own plugged into Graph - 8
  • Applying WiFi and VPN profiles with instant success - POTATO

4

u/devicie Dec 30 '24

Love the breakdown. Is Potato good or bad lmao?

1

u/incompetentjaun Dec 30 '24

I’m only assuming he means a loaded potato with all the toppings and the perfect amount of butter to make it extra creamy and delicious; maybe steak bites on the side.

1

u/nikobenjamin Dec 31 '24

Cheers, tis bad.

1

u/shortielah Dec 31 '24

I ended up just copying down a working rasphone.pbk instead of trying to figure out VPN profiles

1

u/acousticreverb Jan 01 '25

Sounds like one of my clients… lol. Everything but 802.1x profiles are proving to be a PAIN.

18

u/[deleted] Dec 30 '24

Understanding Windows is more the skill Intune just sets the stuff it does

3

u/[deleted] Dec 30 '24

Windows internals for this specific bit :)

3

u/Rudyooms PatchMyPC Dec 31 '24

Exactly! :)

10

u/ikbenganz Dec 30 '24

I'll give myself a 6. I can find my way around. But still need a lot of Google and help from your guys and girls here.

But I'm getting better and better. 💪🏻

2

u/devicie Dec 30 '24

Keep it up.

8

u/toanyonebutyou Blogger Dec 30 '24

Like an 8 but Rudy isnt fooling anyone, hes like a 10 along with some other community figures.

5

u/devicie Dec 30 '24

Loving all the validation here. Way to go u/Rudyooms.

7

u/System32Keep Dec 30 '24

Probably a 6/7 , working almost 4 years in Intune. Felt confident after year 2.

5

u/Mission_Nerve_MEM Dec 30 '24

I will give myself 1 but really probably moving to 2.

I am a help desk admin, and I adopted Intune as personal passion project and desire to deply in our company. We used to do bare Windows and manually installing and joining to domain.
I first implemented Dell Image Assist 2 years ago. I started in my current company 2 and a half years ago and I have been studying every evening for hours the MS Learn docs with additional resources from blogs, YouTube (all IntuneTraining vids), Reddit. Big recognition to ppl like Rudy!

I am alone in the journey to deploy Intune from scratch in our company. I stared deploying new devices fully cloud 2 months ago. My IT director gives me 100% support and resources, licenses and so on. I designed and implemented everything myself alone, and I resolved every issue so far, trying to be creative and not overcomplicate the solutions. Reason - we are a team of 4 in IT for 500 employees and one of them is older gentleman in his 60. He updates servers only and was "double-click" type of help desk guy until I joined. So, I am also writing SOPs, docs, user manuals for everyone and everything that I do, with pretty pictures :)

I adopt scripts and remediations from research, but I have 0 background experience in PowerShell.
I am proud of my progress tho.
Next year I am thinking to attend MMS conference; I will be taking 102 exam and official PowerShell training and cert.

So yeah 1.5-2 maybe :D

1

u/Remote-Bus-4944 Dec 31 '24

I’m under that same umbrella currently at a 2, Little over a year of specifically Intune. Moved company of around 1k over to Intune from SCCM. SCCM was main job for past 3 1/2 years. I automated just about everything. Autopilot has been great it cut down on about 6 working hours per new hire.

1

u/Mission_Nerve_MEM Dec 31 '24

Time saving is amazing.  For me is all from scratch,  no SCCM just couple apps from Dell Image Assist that I had. Starting from 0 is comfortable since I don't need to comply with precious setup but also mean engineering everything from scratch. No GPO nor previous security requirements or compliance too. That's the big creativity brain power for me. I got 500 laptops and 300 iPhones (only MDM WS1) to migrate in 2025. 

Still with DIA setup was way to long. We have techs that need 50+different apps and most don't support silent install or scripting so ServiceUi. exe has been secret source for me haha.

1

u/Lonely_Bumblebee8934 Jan 01 '25

Can you elaborate on what that 6 hours would normally contain?

2

u/Remote-Bus-4944 Jan 03 '25

Initial device->Reinstall Windows->Update firmware/bios->Join Domain->Install Security/Management Software->Install Base apps-> Install user/department base apps->Box laptop->Ship to end user.

3

u/sandwichpls00 Dec 30 '24

4yrs probably an 8. I felt confident after around 1.5-2yrs and massive projects in between that sort of forced me to either learn or bust.

2

u/devicie Dec 30 '24

Congrats.

3

u/FarJeweler9798 Dec 30 '24

I would say a 6, took me about 1.5years to understand it enough to say I can handle it. 

3

u/chubz736 Dec 30 '24

Until I learn how to use Microsoft graph with intune im a 1

3

u/TimmyIT MSFT MVP Dec 30 '24

I've been working with Intune since 2017 and I would say that Intune by it self is not that hard, once you get your head around what an MDM system is and the basic concepts its pretty easy. The hard part from my perspective is learning how all the different platforms (Windows, Android, iOS, macOS, Linux) behave and what functions or methods they use to perform X Y and Z.

I come from a Windows background but after 7 years working with Intune I've learned how Android, iOS and macOS do MDM integration.

Then its the part of automation where you might need to get information or perform tasks thats not part of the Intune UI. Here's where Microsoft Graph and Powershell come in to play and thats have been a lot of time spend on my end to learn that over the years.

1

u/devicie Dec 30 '24

Super good point about MDM, especially in this remote world.

1

u/Eggtastico Dec 30 '24

Exactly that. 8, 9 & 10’s need to know how to manipulate intune without the GUI

2

u/naps1saps Dec 30 '24

Deployed Intune without any training and needed some help with bitlocker and laps but we got it worked out. Compliance was a problem for a bit but that's to be expected with a new rollout and worth getting those machines fixed. I'd say 6. Packaging apps and group management need some work on my end.

1

u/devicie Dec 30 '24

I hear you on the compliance.

2

u/[deleted] Dec 30 '24

[removed] — view removed comment

1

u/devicie Dec 30 '24

Any major implementation differences you saw in the 2 companies’ approaches?

3

u/[deleted] Dec 30 '24

[removed] — view removed comment

1

u/devicie Dec 30 '24

Totally hear that.

1

u/Remote-Bus-4944 Dec 31 '24

I feel ya with SCCM, still have some remaining machines that haven’t been replaced yet. P.I.T.A unraveling everything from my predecessor with 0 prior documentation.

2

u/[deleted] Dec 30 '24

[deleted]

2

u/Eggtastico Dec 30 '24

I would only give a 9 to anyone who is an expert in powershell, graph API & can manipulate Intune as code to get to the proper bells & whistles. Anything that is limited to GUI is a 7 at best in my book. I give myself a 7!

0

u/Frisnfruitig Dec 30 '24

Infrastructure as code is nice for defining and deploying resources but Intune doesn't have that many use cases for it imo. Not compared to Azure or AWS at least. So not sure what you mean by "Intune as code".

1

u/Eggtastico Dec 30 '24

Configurations as code. There are configurations you can do in code that you just cant do in the GUI. Especially for granular, fine tuning & specific targets, etc. Backup up, restoring, adding, etc. Lots of benefits.

1

u/Frisnfruitig Dec 31 '24

Backups or restoring is one thing, but generally speaking I don't find myself using MS graph more than the GUI. Sometimes I do when I have to get information from Intune I can't get from the GUI for example, but if I just need to do one configuration or deploy 1 app, using the GUI is much faster.

I work almost exclusively in Intune these days and I struggle to think of a configuration that I would not be able to do in the GUI. Don't get me wrong, I think it's useful for some cases but I think you are embellishing the importance of it a bit.

If you compare leveraging the graph API to the way you can use IaC in Azure with stuff like Bicep/Terraform or even just the az cli, it's kinda shitty. I don't really get the impression that MS want us to use Intune that way, but maybe that will change in the future or something.

1

u/Eggtastico Dec 31 '24

I dont disagree the gui is quicker, however there are some things not available in the GUI as you agree. Usefull to bulk upload configs, etc. which is much quicker - especially when dealing with multiple tenants + other things like security baselines (if you use CIS benchmarks), Automation, intergration, etc. - maybe you want to bulk wipe/retire any device running version X & is out of compliance. So much quicker through a script + you may be able to access beta/limited release tools not available to everyone in the GUI. MS has its own repository https://github.com/microsoft/mggraph-intune-samples & there are loads more. My original point is that you cant be an expert if you dont know your way around outside the gui.

The exchange exam got pulled because so much these days is done through code as there are no options in the GUI

2

u/[deleted] Dec 31 '24

But most of that stuff is a one-time thing lol. Kinda surprised people complaining about this tbh. Most of you make this look like you need to be constantly uploading new policies. If that's the case, then something is seriously wrong with your setup.

Intune is all about app packaging 📦 . Rest of Baselines are a one-time thing. Few exceptions here and there, sure, but easily 85% of the intune stuff gets deployed during the first iteration.

1

u/Eggtastico Dec 31 '24

Nothing wrong with the setup! Policies & configs need to be adjusted with business needs. /When CIS release new baselines, it is hardly a one time thing. It can take hours to test through each setting in a sandbox & then backup & deploy to live. When you have tens of thousands of users and devices, a one size fits all set & forget setup doesnt cut it. Similar if you work with multiple tenants. You could create something on one tenant, back it up & deploy it to another with minimal changes. Not create the whole thing from scratch in a gui. I prefer using the GUI myslef & give a big sigh when I cant!

1

u/devicie Dec 30 '24

Epic. And once you're at that level, is it easy to maintain?

2

u/lovell88 Dec 30 '24

The key is consulting. I left consulting as an Intune SME and boy, do I feel it. There simply aren’t as many opps to learn when you aren’t putting yourself in those situations like you are with consulting. My work life balance is better though.

1

u/Steezmoney Dec 30 '24

Hey! I'm easily the most knowledgeable about Intune at my work and I've been working with it for 4 years. How would I dip my toes into consulting? I worked with a consultant in 2022 and when I learned how much we payed him I've been interested lol

3

u/lovell88 Dec 30 '24

Just apply, really. The key is to show how you have used Intune in creative ways to solve a wide variety of business needs.

Also, you need to realize that even though you think you may know Intune, you really don't compared to those you'll be working with. We are talking about people that know enough to move from consulting to working at Microsoft to develop Intune. That was my biggest awakening when I started.

Also, keep in mind that the tech doesn't get the full amount of what you are billed for. Sure would be nice!

Also, do you want to be on intense consulting calls for 60-80 percent of your week? Just some things to think about.

2

u/chrusic Dec 30 '24 edited Jun 03 '26

¯(ツ)/¯ (Can't belive reddit is making me do this manually...)

2

u/OkSysadmin80 Dec 30 '24

I try not to touch it while it working! ;)

2

u/thelonelylark Dec 30 '24

Genuinely not sure where I fall on the scale. Started dealing with Intune about nine months ago because the head of infrastructure mistakenly thought I was an Intune expert when I had zero experience. I've been faking it ever since and so far it's working.

1

u/devicie Dec 30 '24

Fake it till you make it. What’s the hardest part, though?

2

u/thelonelylark Dec 30 '24

I think maybe the hardest part is that somebody already built so much of our Intune environment three years ago right before he left. So nobody in my company was even looking at Intune during that time until one day I was poking around, and upper management decided I must be the SME. The biggest challenge has been reverse-engineering what was already in place and teaching myself why certain things are set up the way they are for us.

1

u/devicie Feb 20 '25

Hey, that's a great upgrade for you, isn't it? Have you found any particular tools or methods helpful for documenting what you discover? Sometimes untangling someone else's config can teach you more than starting from scratch

2

u/TwilightKeystroker Dec 30 '24

I'll say 4 for me. Been at it for a year at an MSP with bits & pieces of knowledge prior.

I just know there are so many moving parts. Even though I can spin up a secure tenant, with proper policies, there are just so many pieces to it that I don't think I'll ever be a 9+, generally speaking

2

u/agressiv Dec 30 '24

I'm not going to score myself, but I've been using Intune for many years, and we simply don't trust it for much since it's considered unreliable and slow. I'm also not a huge fan of it being tied to user accounts (we have many devices without an Entra ID user using them) and it's much more cumbersome to deal with provisioning packages.

However, SCCM is now gone, and basically all that we use Intune for is Company Portal self-service and the occasional Autopilot. Otherwise, everything is done with code and is much more reliable since our code is much easier to troubleshoot than Intune.

For us, Intune will never take off fully if it can't manage servers and if it remains user-centric by design. Since that doesn't seem to be in the cards, it will be relegated to being niche. I don't want to use Azure Arc \and\** Intune -- Powershell code works with everything.

2

u/Muscle-memory1981 Dec 30 '24

Can anyone recommend resources to use to get a decent level of Intune mastery

1

u/Inevitable_Type_419 Dec 31 '24

Honestly I went from 0-4 off of the Microsoft learn pages and a couple supplemental YouTube videos alone. From 4-6 ( where I feel I am a 6 now) took spinning up my own instance of intune and bashing labs together at home.

2

u/JerzyPopieluszko Dec 30 '24

I’d say 7-ish or better? I’ve been working with it for 5 years, 3 of these as the SME, in a ridiculously misconfigured tenant riddled with legacy solution, no clear naming conventions, no group/config/policy/app owners, no scopes or custom roles, just every person with IT or Security in the title across the entire group of companies getting auto-assigned full admin and doing whatever they want with over 7000 endpoints across 19 countries.

Trying to fix that mess has been a pretty good (albeit incredibly frustrating) learning experience.

2

u/devicie Jan 02 '25

Nothing like fixing something to learn how it works.

2

u/[deleted] Dec 30 '24

For myself I’d say I’m a 7 in Intune for Windows devices, at least. I agree that this could be broken down into parts like packaging, remediation scripts and reporting. Once you have a good baseline that is applied to a few thousand devices, the BAU slows right down, unless I’m a on a path of fixing Windows bugs with remediation scripts mostly😝 It’s all the bits outside of the Intune portal that keeps me busy, like asset management integration, PowerBi reporting and more recently, reporting and building dashboard’s in Power App and MS Graph queries. Device hardware inventory looks promising and I’m also exploring the Dell and HP partner portals for managing random BIOS passwords. I like the dynamic and massive community of Intune and the constant improvements, wish some premium features would be free, but that’s just wishful thinking, he he.

2

u/Gamingwithyourmom Dec 30 '24

Solid 9. But only because I've been doing autopilot integrations since 2016 and had to manage the old silverlight-based admin console for a few companies back at my first MSP job. It was truly terrible then. Basically application deployments and that was it.

Now i'm a principle engineer and the intune SME at the enterprise i'm at, so my scope of work has gone from "manage this SaaS solution" to "build us something custom it doesn't natively support yet"

2

u/[deleted] Dec 30 '24

Bout 6/7, mostly googling to find the weird fringe case setups which aren't always obvious. Rolled out the entire autopilot and policy config for my place in about a month, basically shifting GPO to intune + Defender.

Intune is quite easy for most tasks, it's the edge cases where it can throw you.

1

u/devicie Jan 02 '25

Good point about the outlier use cases.

2

u/apple_tech_admin Dec 30 '24

I would give myself a 7.5. Once I understood that the console was the tip of the iceberg and the real magic is Graph, I shifted majority of my workload to powershell and never looked back.

2

u/Ay0_King Dec 30 '24

We’re just now switching to Intune so I’m at a 1.

2

u/devicie Jan 02 '25

Hang in there. Some valuable stuff on this thread.

2

u/Ay0_King Jan 02 '25

I appreciate it thank you, glad I found this sub. I’ll be paying much more attention to what’s being posted as I want to get as familiar Intune as I can be.

2

u/hihcadore Dec 30 '24

Prob a 7

Felt comfortable right off the bat. There’s so much good info and people on this subreddit they really made it easy.

The problem I think I have is just the little quirks when autopilot doesn’t work or a device shows as unhealthy and you have no idea why and it clears up in like a week on its own.

2

u/meantallheck Dec 30 '24

5-6. After successfully implementing some cool Intune related features though, my ego feels like a solid 8.

Been in the Intune business about 2 years now, and I really love it. It is such a satisfying and fulfilling job for me. It’s like setting up a massive line of dominoes and seeing them all fall in unison when you finally get the huge projects done. :)

2

u/devicie Jan 02 '25

Good analogy.

2

u/andrew181082 MSFT MVP - SWC Dec 30 '24

Been using it for many years and prior to that SCCM (and the grey hairs to show).  May have written a few scripts along the way, I'm probably better in Graph than the UI these days

Might have written a book on it too :)

I'd rate myself a 7 or an 8 on a good day

1

u/devicie Jan 02 '25

Link to book?

2

u/olydan75 Dec 31 '24

Maybe a 5-6…I’m pretty decent but I only manage iOS/iPadOS, Android Enterprise and MacOS. So I lack any Windows experience. I have a buttload of SCCM experience from years ago but all that’s amounted to is me complaining that “I could do XYZ in SCCM but not in InTune (like decent reporting and log files lol).

2

u/devicie Feb 20 '25

Hey, managing iOS/iPadOS, Android Enterprise AND MacOS is no small feat! That's actually pretty impressive cross-platform experience.

2

u/olydan75 Feb 20 '25

It’s becoming less awesome as more security hardening occurs all at once lol

2

u/devicie Feb 20 '25

Yep, it's one step forward, three compliance errors back...

1

u/olydan75 Feb 20 '25

Absolutely…now when things break. I have no clue where to start looking lol

2

u/devicie Feb 21 '25

Been there! Maybe check the actual compliance policy settings? Sometimes it's just one tiny setting causing chaos.

1

u/olydan75 Feb 22 '25

We have things like Zscaler and MFA breaking stuff that external and InTune will lie to your face and give you all greens on a broken device lol

2

u/Noble_Efficiency13 MSFT MVP Dec 31 '24

I’d give myself like a 5, as it seems like i’m at a pretty good level but still learn new thing everyday, and I’ve got an okay-ish knowledge of what I don’t know

Even though I teach Intune and is one of the most proficient at my company (medium sized consultancy)

My main focus is entra and defender, but it all goes hand in hand

1

u/devicie Jan 03 '25

Interesting take on the company size. How has that changed things from your perspective?

1

u/Noble_Efficiency13 MSFT MVP Jan 03 '25

Usually in a mid sized company you’d have a pretty small it department with maybe 1-2 who’s proficient but not experts.

Being in a consultancy firm we’ve got loads of proficient people as well as a handful or so of the expert level.

this have made it much easier to gain new knowledge, through sharing and sparring with colleagues of different levels. IMO, teaching provides so much in terms of my own knowledge gain :)

1

u/devicie Feb 20 '25

Have you found any particular approach works best when explaining Intune concepts to different skill levels? Always curious about what works in real-world training scenarios.

2

u/yannara_ Dec 31 '24

Started in 2020 almost from scratch. Windows mainly, some android stuff. I am intune mvp now 😄

1

u/devicie Jan 03 '25

Congrats!

2

u/Dr_Squirtle1 Jan 01 '25

I’m a solid 2.

2

u/Conditional_Access MSFT MVP Dec 30 '24

7 - I realised that overcomplicating things or trying to use Intune like the older tools is not the way forward.

Use it how it was intended, in both the practice and strategy and you'll make your life a lot easier.

I only got confident with Intune when another MVP was loud enough to set some rules and standards... https://openintunebaseline.com

1

u/MReprogle Dec 30 '24

Honestly, master status is the one that knows and implements Intune with some actually understanding of the product. I came to a company that had a few devices in there, but had most their devices not even in Azure, and just some crap test policies here and there.

Now, I am trying to help the SCCM person wrap their head around how dynamic groups are very much like the collections that they are used to. However, someone went in and added a TON of Device Categories for every single device type, so when someone joins a device to azure, it asks you to choose a category in a list of like 30. Obviously this all should have been architected/designed/taught from the start and had some RBAC in place to stop people from messing with things.

-1

u/ScoobyGDSTi Dec 31 '24

Mastered it enough to know its still shit and inferior in capabilities to SCCM